Lemmy.world and lemmy.blahaj.zone have been hit with a JavaScript injection attack it seems.

27 points

you are being redirected to a porn site. sorry for the convenience.

permalink
report
reply
10 points

it’s also preventing all other content and (hopefully) temporarily killing the instance, I know you’re probably just joking but this ain’t good

permalink
report
parent
reply
3 points

oh hell no, I mean heck no, this is totally bad news bears. They just got clowned and if you don’t laugh at yourself someone will do it for you.

permalink
report
parent
reply
2 points

I used to watch porn. I still do, but I used to, too.

permalink
report
parent
reply
13 points

Looks like Lemmy code has a security vulnerability, persistent XSS, that allows injection of Javascript into the sidebar and comments. That allowed the attacker to force load NSFW content even after lemmy.world admins cleaned up the first attack.

Looks like the injected JS code also steals login tokens from your browser, seems some admin accounts got compromised this way.
Probably a good idea to not visit Lemmy sites for time being (or block execution of Javascript in your browser, which is always a good idea).

permalink
report
reply
2 points

Not just sidebar or comments, but anywhere markdown is used. The issue is the markdown editor. This is the current proposed fix.

permalink
report
parent
reply
11 points

Issue 1895 opened and patch purposed for the core issue. The markdown editor does no escaping input on custom emojis. This is likely why users on app were seeing text and not getting the redirect.

permalink
report
reply
2 points

🙃

permalink
report
parent
reply

Fediverse

!fediverse@kbin.social

Create post

This magazine is dedicated to discussions on the federated social networking ecosystem, which includes decentralized and open-source social media platforms. Whether you are a user, developer, or simply interested in the concept of decentralized social media, this is the place for you. Here you can share your knowledge, ask questions, and engage in discussions on topics such as the benefits and challenges of decentralized social media, new and existing federated platforms, and more. From the latest developments and trends to ethical considerations and the future of federated social media, this category covers a wide range of topics related to the Fediverse.

Community stats

  • 3

    Monthly active users

  • 680

    Posts

  • 3.9K

    Comments

Community moderators